{"id":"508dbeae-e0cb-4852-b41a-048028a106b3","engagementId":"a2278467-0ba6-484f-b434-4413c7270eec","data":{"brief":{"id":"5855d8e2-e449-487d-b5a8-82a1e6a19355","name":"Plusgrade Vulnerability Disclosure Program","tagline":"Plusgrade powers the global travel industry with ancillary offerings and loyalty expertise to create incredible travel experiences and new revenue opportunities.","description":"\u003cp\u003eNo technology is perfect and Plusgrade believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology.  We care about our partners' information security, and we're ready to work with security researchers to improve the security of our services.  Plusgrade believes that ethical security research performed in good-faith provides an invaluable public service.  \u003c/p\u003e\n\n\u003cp\u003eWe are excited for you to participate as a security researcher to help us identify vulnerabilities in our web applications.\u003c/p\u003e\n\n\u003cp\u003eGood luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003e\u003cstrong\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Plusgrade not listed in the targets section, or the  additional resources tab, is out of scope.  If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Plusgrade, you can report it to this program.\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003ePlease be cautious with the use of vulnerability scanners on this program. Custom scripts and fuzzing tools are permitted, however if using an automated tool or script please throttle traffic to six requests per second or less.\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eRemote code execution (RCE)\u003c/li\u003e\n\u003cli\u003eInjection attacks (SQL injection, Command injection, XML injection, CRLF injection)\u003c/li\u003e\n\u003cli\u003eXML external entity (XXE)\u003c/li\u003e\n\u003cli\u003eCross site scripting (XSS)\u003c/li\u003e\n\u003cli\u003eServer side request forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eCross site request forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eDirectory traversal - local file inclusion\u003c/li\u003e\n\u003cli\u003eAuthentication/authorization bypass\u003c/li\u003e\n\u003cli\u003ePrivilege escalation\u003c/li\u003e\n\u003cli\u003eInsecure direct object reference (IDOR)\u003c/li\u003e\n\u003cli\u003eSite and server misconfigurations\u003c/li\u003e\n\u003cli\u003eWeb cache deception\u003c/li\u003e\n\u003cli\u003eCross-Origin Resource Sharing misconfiguration (CORS)\u003c/li\u003e\n\u003cli\u003eOpen redirect\u003c/li\u003e\n\u003cli\u003eInformation disclosure\u003c/li\u003e\n\u003cli\u003eRequest smuggling\u003c/li\u003e\n\u003cli\u003eMixed content\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope Areas\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eCorporate email and file storage\u003c/li\u003e\n\u003cli\u003eCorporate VPN\u003c/li\u003e\n\u003cli\u003e3rd party applications and services\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExpectations\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eMake a good-faith effort to avoid harm to Plusgrade Inc, our subsidiaries, our customers, and our end-users, including, but not limited to: privacy violations, destruction of data, and interruption or degradation of our services.\u003c/li\u003e\n\u003cli\u003eDo not access or attempt to access Plusgrade offices, data centers, or user accounts.\u003c/li\u003e\n\u003cli\u003eDo not test for spam, perform phishing, social engineer, or intentionally cause denial of service issues for Plusgrade services.\u003c/li\u003e\n\u003cli\u003eDo not access or attempt to access our partner's systems, data centers, user accounts, or attempt other forms of penetration testing without the direct, written approval of the system owner.\u003c/li\u003e\n\u003cli\u003eComply with all applicable laws and regulations; do not disrupt or compromise any data that is not your own, or further exploit a confirmed vulnerability.\u003c/li\u003e\n\u003cli\u003eIf a vulnerability provides unintended access to data, limit the amount of data you access to the minimum required to demonstrate a proof of concept. After Plusgrade validates your report, properly dispose of all copies of the data.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen making submissions that involve deep links, magic links or personalized links, please include the details on how the link was obtained.\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eDisclosure:\u003c/h2\u003e\n\n\u003cp\u003eThis program or engagement does not allow disclosure. You may not release information about vulnerabilities found in this program or engagement to the public.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"3b04ceeb-54cc-4679-b754-fb6a818b5778","name":"Upgrades, Seating \u0026 More","targets":[{"id":"04f3b4eb-32e8-49e0-aa1d-13d19df9ab90","uri":"https://www.plusgrade.com/","name":"*.plusgrade.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c51e0af5-7214-49e1-a923-a6933dc8ac79","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"04f3b4eb-32e8-49e0-aa1d-13d19df9ab90"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"04f3b4eb-32e8-49e0-aa1d-13d19df9ab90"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"04f3b4eb-32e8-49e0-aa1d-13d19df9ab90"}],"recentChangeFlags":null},{"id":"3104a85c-dba8-456d-80b4-89dea6396a4f","uri":"https://www.upstay.tech","name":"*.upstay.tech","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"772cdeda-b0c5-4ec2-8b6e-ae3fc88a9074","sortOrder":0},"sortOrder":0,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"3104a85c-dba8-456d-80b4-89dea6396a4f"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"3104a85c-dba8-456d-80b4-89dea6396a4f"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"3104a85c-dba8-456d-80b4-89dea6396a4f"}],"recentChangeFlags":null},{"id":"9de5ebe2-6384-4609-b326-53b9b32cf1cf","uri":"","name":"*.upgrd.co","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"95a56db2-0ea6-4543-b8c2-b3d971a93297","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"9de5ebe2-6384-4609-b326-53b9b32cf1cf"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"9de5ebe2-6384-4609-b326-53b9b32cf1cf"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"9de5ebe2-6384-4609-b326-53b9b32cf1cf"}],"recentChangeFlags":null},{"id":"21e244e7-b700-460a-8126-8a9cf36a4b96","uri":"","name":"Additional scope included under resources tab","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"bcc4f094-cf29-42b8-b90c-14c030b472eb","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eThis target group focuses on upgrades and ancillary revenue for the global travel industry.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"d9c2db6f-1bce-4351-9b50-cbf8eec1782e","name":"Loyalty","targets":[{"id":"ad24781a-4885-474c-b2ee-4b76bb5a6e07","uri":"","name":"*.points.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1a43f6c1-97ea-4765-a014-92e2469dda2b","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"ad24781a-4885-474c-b2ee-4b76bb5a6e07"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"ad24781a-4885-474c-b2ee-4b76bb5a6e07"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"ad24781a-4885-474c-b2ee-4b76bb5a6e07"}],"recentChangeFlags":null},{"id":"37bb12cd-1811-4f0b-8157-e82dd6762cce","uri":"","name":"Additional scope included under resources tab\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7934be4d-961c-484b-be06-98ebfd82a2db","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eThis target group focuses on loyalty programs for the global travel \u0026amp; hospitality industry.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"bee991bb-1792-499b-93ac-3be0f390c662","name":"Out of Scope Targets","targets":[{"id":"0509297f-7aca-4b0b-a9cb-a7b272f52e8d","uri":"","name":"Partner Website \u0026 Applications","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f16a0a3c-4023-4c60-a7e9-89353f07887b","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"5afb6109-34b6-442f-a12d-07321b2936e8","uri":"","name":"Anything not explicitly listed as in-scope","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"90e4ea80-339e-408a-8564-ba1957f58435","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eWe realize that it can be confusing where Plusgrade\u0026#39;s services end and our partner\u0026#39;s service begin (and vice-versa).  We often display branded pages on behalf of our partners.  \u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[{"id":"5ad73b67-7f29-494a-b10b-5301cde0063b","attachmentPath":"https://bugcrowd.com/engagements/plusgrade-vdp-pro/attachments/5ad73b67-7f29-494a-b10b-5301cde0063b","name":"Upgrades_and_Seating_and_More_Vanity_Domains.pdf","filename":"Upgrades_and_Seating_and_More_Vanity_Domains.pdf","description":"Additional domains that are considered in scope for Upgrades, Seating and More.","icon":"fileOther","size":21397,"sizeLabel":"20.9 KB","uploadedAt":"11 Sep 2024","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/plusgrade-vdp-pro/attachments/5ad73b67-7f29-494a-b10b-5301cde0063b"},{"id":"9d204418-d792-44f0-b856-97ab9e5cb6eb","attachmentPath":"https://bugcrowd.com/engagements/plusgrade-vdp-pro/attachments/9d204418-d792-44f0-b856-97ab9e5cb6eb","name":"Loyalty-Vanity-Targets.txt","filename":"Loyalty-Vanity-Targets.txt","description":null,"icon":"fileOther","size":761,"sizeLabel":"761 Bytes","uploadedAt":"16 Oct 2024","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/plusgrade-vdp-pro/attachments/9d204418-d792-44f0-b856-97ab9e5cb6eb"}],"engagement":{"id":"a2278467-0ba6-484f-b434-4413c7270eec","code":"plusgrade-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"adb7a6fc-3bcf-4096-8a9f-6a6be74a2c31","startsAt":"2023-07-13T12:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/187f/368f/deac4e48/bfab2decdcd9127b3b0ac882c43caf19_plusgrade_logo.jpeg","logoBackgroundColor":"#2a2d40","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-05-07T16:57:55.204Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/plusgrade-vdp-pro","changelogs":"/engagements/plusgrade-vdp-pro/changelog","submissions":null,"announcements":"/engagements/plusgrade-vdp-pro/announcements","hallOfFame":"/engagements/plusgrade-vdp-pro/hall_of_fames","crowdstream":null},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/plusgrade-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=plusgrade-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/plusgrade-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/plusgrade-vdp-pro/changelog","publishedAt":"2025-05-07T16:57:55.234Z","engagementChangelogUrl":"/engagements/plusgrade-vdp-pro/changelog/508dbeae-e0cb-4852-b41a-048028a106b3","createUserFeedbacksUrl":"/engagements/plusgrade-vdp-pro/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}